Hengyan Zhang, Hengyan Zhang, Weizhe Zhang, Yuming Feng · 5 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,615 results · page 32 of 68
Hengyan Zhang, Hengyan Zhang, Weizhe Zhang, Yuming Feng · 5 authors
No abstract is available for this record.
Ramiz Salama, Fadi Al‐Turjman, Chadi Altrjman, Sumit Kumar · 5 authors
Text mining was used to examine the academic publications on blockchain technology and cybersecurity that were published in huge digital libraries. Automated text mining methods like topic modeling and key word extraction are utilized in this literature study to extract topics from a vast corpus of literature. This article emphasizes the cross-disciplinary character of blockchain technology in the context of cybersecurity. The outcomes also show the risks and security holes that emerge as blockchain technology matures. Nevertheless, the investigation this article also outlines research gaps in the area of computer security and recommends research directions for future work that will be necessary to create safe blockchain platforms.
Namya Aankur Gupta, Mansi Bansal, Seema Sharma, Deepti Mehrotra · 5 authors
Smart contract technology in today’s world is becoming really popular as it is changing the way transactions in industrial and commercial fields work. Smart contracts are scripts that are stored on the blockchain's distributed network and are used to carry out transactions consequently based on specific criteria without the need for third-party consent. Hence, they can help to minimize the costs of administration and services and at the same time, enhance operational efficiencies and lessen the risk. Despite the smart contracts having a lot of potential to unleash a new surge of technology, it is accompanied with a number of challenges that hinder the privacy and security of the user. Some vulnerabilities are reentrancy, timestamp, delegate call and integer underflow. To resolve these issues, the goal is to develop a smart contract vulnerability detection model based on machine learning algorithms.
Vasavi Chithanuru, Mangayarkarasi Ramaiah
Summary Recently, Blockchain cryptographic distributed transaction ledger technology finds its usage in many applications. The application's ledgers implemented through Blockchain, ensures tamper‐proof transactions, and in turn the applications became robust enough against cyber‐attack But still adversaries put forward their efforts in detecting the vulnerabilities in the infrastructure to execute their ill intent. In the literature, many counter measures techniques are presented to address the security breaches on the Blockchain. Detecting as well mitigating from the possible anomalies against on blockchain infrastructure through AI techniques is the greatest attempt of this article, and which is much needed now. Hence, this review article enlightens the readers with the essence of cyber security, the security aspects of Blockchain, its infrastructure vulnerabilities, various Blockchain‐enabled use cases along with the their challenges. Primarily, anomaly detection on Blockchain infrastructure through Artificial Intelligence Techniques is focused. A detailed analysis of Artificial Intelligence Techniques in detecting the anomalies with the help of Blockchain and also how these two technologies complement each other was demonstrated with the help of suitable use cases. The merits, challenges along with the possible future directions, while integrating Blockchain with Artificial Intelligence Techniques are presented for the benefit of research community.
Mohsin Dhali, Shafiqul Hassan, Saghir Munir Mehar, Khurram Shahzad · 5 authors
Purpose The purpose of the study is to show that divergent perceptions among regulators, the regulated and the associated regulatory bodies across multiple jurisdictions regarding the nature and functionality of cryptocurrencies hamper the development of a more comprehensive and coherent regulatory framework in curbing crimes and other related risks associated with cryptocurrencies. Design/methodology/approach The study has used a descriptive doctrinal legal research method to investigate and understand the insights of existing laws and regulations in four selected jurisdictions concerning cryptocurrencies and how these laws could be further improved and developed to reduce crypto-related crimes. Furthermore, the study has also used a comparative research method to conceptualize the contours of the new legal discourse emerging from cryptocurrencies to adopt and implement a sound regulatory framework. Findings The study illustrated that divergent regulatory treatment among different jurisdictions might suffocate novel digital innovations such as cryptocurrency. These fragmented regulatory approaches by various jurisdictions question the sustainability of the present national legislation adopted to regulate cryptocurrencies. Looking into other jurisdictional developments in regulating cryptocurrencies, it is apparent that a concerted regulatory approach is needed to minimize the abuse of this innovation. Research limitations/implications The study has implications for regulators and policymakers to review the current regulatory framework for regulating cryptocurrencies to prevent regulatory arbitrage. The divergent legislative measures concerning cryptocurrency among different jurisdictions question the sustainability of these legislative initiatives, considering the evolving and borderless nature of cryptocurrency. Therefore, this paper will help regulators to consider the present legislative gaps in establishing a common global regulatory approach in the crypto sphere. Originality/value The study contributes to the existing body of literature by examining the regulatory frameworks of four jurisdictions, namely, the USA, Canada, China and the EU, related to cryptocurrencies, with a discussion on the development of cryptocurrencies-related laws among these four jurisdictions and their sustainability in curbing crimes in the Darknet.
Casey Watters
In August of 2022, the United States Department of Treasury sanctioned the virtual currency mixer Tornado Cash, an open-source and fully decentralised piece of software running on the Ethereum blockchain, subsequently leading to the arrest of one of its developers in the Netherlands. Not only was this the first time the Office of Foreign Assets Control (OFAC) extended its authority to sanction a foreign ‘person’ to software, but the decentralised nature of the software and global usage highlight the challenge of establishing jurisdiction over decentralised software and its global user base. The government claims jurisdiction over citizens, residents, and any assets that pass through the country’s territory. As a global financial center with most large tech companies, this often facilitates the establishment of jurisdiction over global conduct that passes through US servers. However, decentralised programs on blockchains with nodes located around the world challenge this traditional approach as either nearly all countries can claim jurisdiction over users, subjecting users to criminal laws in countries with which they have no true interaction, or they limit jurisdiction, thereby risking abuse by bad actors. This article takes a comparative approach to examine the challenges to establishing criminal jurisdiction on cryptocurrency-related crimes.
Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou · 7 authors
The growth of the decentralized finance (DeFi) ecosystem built on blockchain technology and smart contracts has led to an increased demand for secure and reliable smart contract development. However, attacks targeting smart contracts are increasing, causing an estimated \$6.45 billion in financial losses. Researchers have proposed various automated security tools to detect vulnerabilities, but their real-world impact remains uncertain. In this paper, we aim to shed light on the effectiveness of automated security tools in identifying vulnerabilities that can lead to high-profile attacks, and their overall usage within the industry. Our comprehensive study encompasses an evaluation of five SoTA automated security tools, an analysis of 127 high-impact real-world attacks resulting in \$2.3 billion in losses, and a survey of 49 developers and auditors working in leading DeFi protocols. Our findings reveal a stark reality: the tools could have prevented a mere 8% of the attacks in our dataset, amounting to \$149 million out of the \$2.3 billion in losses. Notably, all preventable attacks were related to reentrancy vulnerabilities. Furthermore, practitioners distinguish logic-related bugs and protocol layer vulnerabilities as significant threats that are not adequately addressed by existing security tools. Our results emphasize the need to develop specialized tools catering to the distinct demands and expectations of developers and auditors. Further, our study highlights the necessity for continuous advancements in security tools to effectively tackle the ever-evolving challenges confronting the DeFi ecosystem.
Petar Radanliev
<p>The first cryptocurrency was invested in 2008/09, but the Blockchain-Web3 concept is still in its infancy, and the cyber risk is constantly changing. Our cybersecurity should also be adapting to these changes to ensure security of personal data and continuation of business for organisations. This review paper starts with a comparison of existing cybersecurity standards and regulations from the National Institute of Standards and Technology (NIST) and the International Organization for Standardization (ISO) - ISO27001, followed by a discussion on more specific and recent standards and regulations, such as the Markets in Crypto-Assets Regulation (MiCA), Committee on Payments and Market Infrastructures and the International Organisation of Securities Commissions (CPMI-IOSCO), and more general cryptography and post-quantum cryptography, in the context of cybersecurity. These topics are followed up by a review of recent technical reports on cyber risk/security and a discussion on cloud security questions. Comparison of Blockchain cyber risk is also performed on the recent EU standards on cyber security, including European Cybersecurity Certification Scheme (EUCS) – cloud, and additional US standards – The National Vulnerability Database (NVD) Common Vulnerability Scoring System (CVSS). The study includes a review of Blockchain endpoint security, and new technologies e.g., IoT. The research methodology applied is a review and case study analysing secondary data on cybersecurity. The research significance is the integration of knowledge from the United States (US), the European Union (EU), the United Kingdom (UK), and international standards and frameworks on cybersecurity that can be alighted to new Blockchain projects. The results show that cybersecurity standards are not designed in close cooperation between the two major western blocks - US and EU. In addition, while the US is still leading in this area, the security standards for cryptocurrencies, internet-of-things, and blockchain technologies have not evolved as fast as the technologies have. The key finding from this study is that although the crypto market has grown into a multi-trillion industry, the crypto market has also lost over 70% since its peak, causing significant financial loss for individuals and cooperation’s. Despite this significant impact to individuals and society, cybersecurity standards and financial governance regulations are still in their infancy.</p>
Adam W. Turner, Muhammad Ikram, Allon J. Uhlmann
This research develops a methodology to identify transactions through data-driven tracking and analysis of ransomware-Bitcoin payment networks [30]. We demonstrate the methodology by applying the GraphSAGE embedding algorithm to the WannaCry ransomware-Bitcoin cash-out network. The paper takes a data-driven approach to building a machine learning system that allows analysts to define features relevant to ransomware-Bitcoin payment networks.
Samantha Jeyakumar, Eugene Yugarajah Andrew Charles, Punit Rathore, Marimuthu Palaniswami · 6 authors
The study analysed the importance of blockchain transaction features to identify suspicious activities. The feature engineering process involves exploiting domain knowledge, applying intuition, and performing a time-consuming series of trial-and-error extractions. Manually overseeing this process significantly impacts the performance of model generation. We address this challenge with an automated feature engineering approach to extract the various features from blockchain transactions. Also, we engineered a set of new features based on statistical measures and graph representation. We demonstrate that the proposed approach can be applied to various blockchain transaction datasets, including Bitcoin and Ethereum. The engineered features were tested against eight classifiers, including random forest, XG-boost, Silas, and neural network-based classifiers to identify the suspicious behaviour of transactions
Ziniu Shen, Yunfang Chen, Wei Zhang
The blockchain 2.0 age, marked by smart contract and Ethereum, has arrived couple years ago. Its technologies have expanded the application scenarios of blockchain technology and driven the boom of decentralized Finance. However, smart contract vulnerabilities and security issues are also emerging one after another. Hackers have exploited these vulnerabilities to cause huge economic losses. In recent years, a large amount of research on the analysis and detection of smart contract vulnerabilities has emerged, but there has been no common detection tool and corresponding test dataset. In this paper, we build GSVD dataset (Generalized Smart Contract Vulnerability Dataset) consisting four offline datasets using smart contracts on two chains, Polygon and BSC: two small Solidity datasets consisting of 153 labeled smart contract source codes, which can be used to test the performance of vulnerability mining tools; two large Solidity datasets consisting of 52,202 un labeled real smart contract source codes that can be used to verify the correctness of various theories and tools under a large number of real data conditions. At the same time, this paper integrates the scripting framework accompanying the GSVD dataset, which can execute a variety of popular automated vulnerability detection tools on top of these datasets and generate analysis results of contracts and potential vulnerabilities. We tested the Minor dataset under GSVD using three tools (Slither, Manticore, Mythril) that are kept up to date and found that the combined use of all tools detected 61.1% of labeled vulnerabilities, of which Mythril has the highest detection rate of 42.6%. It is not difficult to conclude that there`re still ample room for advancement for current smart contract vulnerability mining tools because of their underlying methods. Besides, our dataset can contribute to the ultimate target greatly by providing mining tools plenty real contracts information.
Salma Elhag, Sara Dirbi Alshehri
No abstract is available for this record.
Kewei Zhao, Guixin Dong, Dong Bian
In recent times, there has been a swift advancement in the field of cryptocurrency. The advent of cryptocurrency has provided us with convenience and prosperity, but has also given rise to certain illicit and unlawful activities. Unlike classical currency, cryptocurrency conceals the activities of criminals and exposes their behavioral patterns, allowing us to determine whether present cryptocurrency transactions are legitimate by analyzing their behavioral patterns. There are two issues to consider when determining whether cryptocurrency transactions are legitimate. One is that most cryptocurrency transactions comply with laws and regulations, but only a small portion of them are used for illegal activities, which is related to the sample imbalance problem. The other issue concerns the excessive volume of data, and there are some unknown illegal transactions, so the data set contains an abundance of unlabeled data. As a result, it is critical to accurately distinguish between which transactions among the plethora of cryptocurrency transactions are legitimate and which are illegal. This presents quite a difficult challenge. Consequently, this paper combines mutual information and self-supervised learning to create a self-supervised model on the basis of mutual information that is used to improve the massive amount of untagged data that exist in the data set. Simultaneously, by merging the conventional cross-entropy loss function with mutual information, a novel loss function is created. It is employed to address the issue of sample imbalance in data sets. The F1-Score results obtained from our experimentation demonstrate that the novel loss function in the GCN method improves the performance of cryptocurrency illegal behavior detection by four points compared with the traditional loss function of cross-entropy; use of the self-supervised network that relies on mutual information improves the performance by three points compared with the original GCN method; using both together improves the performance by six points.
Umair B. Chaudhry, Aysha Kattakath Mulangat Hydros
Abstract Cyber security in the banking sector is of high importance nowadays. The rate of cyberattacks is spiking every year, and the implementation of strong cybersecurity models is required to ensure the confidentiality and integrity of data. Since protecting a bank requires a wide range of security practices, this paper focuses on protecting the bank resources from malicious actors and securing the transactions using a blockchain consensus mechanism that uses a zero‐trust security approach among the participants in the transaction. In addition to the framework, an algorithm for blockchain‐based online transactions was designed to make use of practical implementation in the future. The ideas formulated during the research and literature review were integrated to design the framework and the algorithm. The proposed framework ensures that the security of the banking sector can be enhanced by adopting the zero‐trust concept and blockchain technology. The consensus algorithms used for the transaction make it immutable and decentralized. Zero‐trust principles adopted in the model ensure the confidentiality and integrity of the banking system.
Zhigang Xu, Xingxing Chen, Xinhua Dong, Hongmu Han · 10 authors
Efficient and convenient vulnerability detection for smart contracts is a key issue in the field of smart contracts. The earlier vulnerability detection for smart contracts mainly relies on static symbol analysis, which has high accuracy but low efficiency and is prone to path explosion. In this paper, the authors propose a static method for vulnerability detection based on deep learning. It first disassembles Ethereum smart contracts into opcode sequences and then converts the vulnerability detection problem into a natural language text classification problem. The word vector method is employed to map each opcode to a uniform vector space, and the opcode sequence matrix is trained by the TextCNN method to detect vulnerabilities. Furthermore, a code obfuscation method is given to enhance and balance the dataset, while three different opcode sequence generation methods are proposed to construct features. The experimental results verify that the average prediction accuracy of each smart contract exceeds 96%, and the average detection time is less than 0.1 s.
Shyam Mehta, K. Shantha Kumari, Paras Jain, Harshal Raikwar · 5 authors
When a cognizable violation like murder, abduction, rape, theft, etc. is committed, a victim or someone acting on their behalf must submit an electronic first information report (e-FIR) to the police station. Due to the centralized nature of the e-FIR database, it is possible for the offense’s record to be hacked, and it is also possible for fake e-FIRs to be purposefully registered. Data transparency and integrity are therefore major issues with the e-FIR database. Indian government launched nation-wide Crime and Criminal Tracking Network and Systems (CCTNS) during 2009 and it is an efficient e-governance system. This paper provides a blockchain solution to handle the complaints given on both cognizable and non-cognizable complaints. Using real-world examples from previous events, the technology and security underlying the use of blockchain will be discussed. Police will file an e-FIR, which will be validated by the authorities, and on acceptance of the FIR, it will be encrypted and stored as a hash along with the timestamp and hash of the next block. Now, how blockchain makes it secure is that it doesn’t let anybody make changes to the FIR without proof of work and a vote of consensus in which a majority of the blockchain must agree to the change. The hash will be stored in smart contracts using Ethereum. Our findings demonstrate a trade-off between the number of transactions contained in a single block on the blockchain ledger and the security level of various hashing algorithms for the offence data.
Benjamin Leo
Cryptocurrencies, first introduced in 2009, have rapidly grown in value, volume, and use. The sentiment that they are no more than a passing fad and need not be dealt with by scholars or policymakers remains but is no longer legitimate. Hostile actors such as terrorist groups and sanctioned states use cryptocurrencies to finance activities ranging from deadly attacks to rogue nuclear programs. The use of cryptocurrencies by legitimate actors brings far less dramatic externalities but still presents serious issues, such as the vulnerability of citizens to cryptocurrency-related scams, lost tax revenue, and the stress cryptocurrencies place on countries' electrical grids. This chapter provides readers with an understanding of exactly how cryptocurrencies function, how hostile actors use them, and how governments respond so that they may better understand the challenges posed by cryptocurrencies and how they might be addressed.
Thomas E. Dearden, Samantha E. Tucker
Transactions on the darknet are notoriously difficult to examine. Prior criminological research has generally used web scraping and qualitative text analysis to examine illegal darknet markets. One disadvantage of this process is that individuals can lie. Fortunately for researchers, the currency used for transactions on the darknet, cryptocurrency, is designed to be tracked. In this article, we examine transactions from a former darknet marketplace, AlphaBay. Using the blockchain, we examine the interconnectedness of both legal and illegal cryptocurrencies. In addition, we provide a structured approach to quantitatively examine the Bitcoin blockchain ledger, offering both the tools and our own experiences for other researchers interested in such approaches. While cybersecurity, information technology, accounting, and other disciplines can examine the financial data itself, we believe that criminologists can provide additional benefits in pattern analysis and organizing the context and theory around the transactions. Our results show that cryptocurrency transactions are generally identifiable (90%) and involve likely illegal transactions, transactions that attempt to obfuscate other transactions, and legal transactions. We end with a discussion of newer cryptocurrencies and related technology and how they will likely shape future work.
Casimer DeCusatis, Brian Gormanly, John Iacino, Reed Percelay · 6 authors
Blockchain, smart contracts, and related concepts have emerged in recent years as a promising technology for cryptocurrency, NFTs, and other areas. However, there are still many security issues that must be addressed as these technologies evolve. This paper reviews some of the leading social engineering attacks on smart contracts, as well as several vulnerabilities which result from insecure code development. A smart contract test bed is constructed using Solidity and a Metamask wallet to evaluate vulnerabilities such as insecure arithmetic, denial of service, and re-entrancy attacks. Cross-chain vulnerabilities and potential vulnerabilities resulting from layer 2 side-chain processing were also investigated. Mitigation best practices are proposed based on the experimental results.
Lakshmi P. Krishnan, Iman Vakilinia, Sandeep Reddivari, Sanjay Ahuja
With the emergence of cryptocurrencies and Blockchain technology, the financial sector is turning its gaze toward this latest wave. The use of cryptocurrencies is becoming very common for multiple services. Food chains, network service providers, tech companies, grocery stores, and so many other services accept cryptocurrency as a mode of payment and give several incentives for people who pay using them. Despite this tremendous success, cryptocurrencies have opened the door to fraudulent activities such as Ponzi schemes, HYIPs (high-yield investment programs), money laundering, and much more, which has led to the loss of several millions of dollars. Over the decade, solutions using several machine learning algorithms have been proposed to detect these felonious activities. The objective of this paper is to survey these models, the datasets used, and the underlying technology. This study will identify highly efficient models, evaluate their performances, and compile the extracted features, which can serve as a benchmark for future research. Fraudulent activities and their characteristics have been exposed in this survey. We have identified the gaps in the existing models and propose improvement ideas that can detect scams early.
Kai Wang, Maike Tong, Changhao Wu, Jun Pang · 7 authors
The development of clustering heuristics has demonstrated that Bitcoin is not completely anonymous. Currently, existing clustering heuristics only consider confirmed transactions recorded in the Bitcoin blockchain. However, unconfirmed transactions in the mempool have yet to be utilized to improve the performance of the clustering heuristics. In this paper, we bridge this gap by combining unconfirmed and confirmed transactions for clustering Bitcoin addresses effectively. First, we present a data collection system for capturing unconfirmed transactions. Two case studies are performed to show the presence of user behaviors in unconfirmed transactions not present in confirmed transactions. Next, we apply the state-of-the-art clustering heuristics to unconfirmed transactions, and the clustering results can reduce the number of entities after applying, for example, the co-spend heuristics in confirmed transactions by 2.3%. Finally, we propose three novel clustering heuristics to capture specific behavior patterns in unconfirmed transactions, which further reduce the number of entities after the application of the co-spend heuristics by 9.8%. Our results demonstrate the utility of unconfirmed transactions in address clustering and further shed light on the limitations of anonymity in cryptocurrencies. To the best of our knowledge, this paper is the first to apply the unconfirmed transactions in Bitcoin to cluster addresses.
Pardon Ramazhamba, Hein S. Venter
Abstract The South African Local Government (SALG) uses the tendering system to procure goods and services. Some of these tendering projects are aimed at promoting socio-economic and industrial policies. Hence, the tendering system used by SALG should be fair, transparent, competitive, cost-effective, equitable, and free from corruption. However, the mismanagement of the tendering system might lead to interruption of operations, late service delivery, rising costs, and most importantly, fraud and corruption. The use of paperwork to share project information might lead to the mismanagement of the tendering project because it might contribute towards illicit altering of project information during the process. The purpose of this study is to develop a Blockchain prototype that might be used to securely share project information with all the parties interested in the tendering project. It is recommended that the adoption of the proposed solution will enable various organisations to have access to real-time data, allowing them to have access to the entire project history regardless of their geographical location. Access to real-time data would promote real-time auditing and digital forensic investigations because both auditors and investigators will have access to credible digital evidence or project information of their interest in real-time.
Tingyu Ma
As computer technology develops, the popularity of cryptocurrencies and their use will grow, and the newer people enter the industry. It changes the business model between organized businesses out of the need for another trusted party. Blockchain smart contracts can automatically enforce agreed contract between two unknowns. Briefly introduce Ethereum, a cryptocurrency, and focus on the security of its smart contracts in internet transactions. Ethereum was the first platform to support high-level programming languages to implement smart contracts, and the second largest blockchain platform, providing a runtime environment for essentially all Decentralized Finance applications. Bitcoin also supports the development and execution of smart contracts, but it is affected by the nature of the programming language used, and it hardly supports transactions except for verifying signatures. Because smart contracts can support a variety of large transactions, some security vulnerabilities can be extremely costly. In an extensive search and survey, the issue of smart contracts for the Ethereum blockchain was valued. The article will discuss some of the existing or former contract vulnerabilities and their solutions. It concludes with a discussion of the future direction of the smart contract space and provides some suggestions for those researching the field.
Sathish Kumar S., S. Thowseaf
Despite the rise in Bitcoin scams, there is a lack of thorough research on the subject. Sophisticated scammers and money launderers can take advantage of Bitcoin mixing services and exchanges. Bitcoin mixing services will send more coins to the customer's address after deducting the mixing cost. The frequency and amount of payments/fees may seem unpredictable, but this is the reality. Criminals use bitcoin mixing services to disguise the source of lost profits and pay securely through cryptocurrency exchanges for anonymous use. Bitcoin's normative unpredictability and organizational opacity attract people with shady intentions, such as supporting rebels or buying drugs. The results of this scoping study show that investigations into cryptocurrency fraud are increasing in scope and depth, but are in the early stages of examining future concerns and circumstances.